Bitcoin and Ethereum-linked protocols exploited for $35M across multiple attacks in hours, targeting compromised keys and validation mechanisms in cross-chain systems.
Security & Exploits ·
Multiple Bitcoin and Ethereum-connected protocols suffered losses exceeding $35 million across a six-hour window of coordinated attacks. The AFX perpetuals exchange on Arbitrum was hit for approximately $24.15 million via its bridge infrastructure, while Verus saw its Ethereum bridge drained of roughly $7.54 million, and B² Network lost about $3.86 million from its staking contract. Security researchers BlockAid and PeckShield documented the incidents, which exposed systemic vulnerabilities in how cross-chain systems manage permissions and validate transactions.
None of the three exploits broke fundamental cryptographic mechanisms. Instead, attackers exploited logic flaws in contract execution or seized control through compromised private keys and upgrade permissions. The Verus breach was particularly striking: it targeted the identical vulnerability that had caused an $11.5 million loss in May, using the same bridge import mechanism. After that earlier hack, Verus recovered and redeposited funds back into the vulnerable bridge on July 8, leaving it exposed to a repeat drain roughly two weeks later.
The attacks underscore recurring design weaknesses in cross-chain systems, particularly around off-chain components such as key management and governance permissions. While each protocol operated as its code intended, the rules governing those systems and the protection of administrative access proved insufficient to prevent large-scale theft.